# Latest

**URL:** https://discuss.elastic.co/latest.md?page=693

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 694

---

## [Auditbeat btmp file monitoring glitch (saved size or offset illogical)](https://discuss.elastic.co/t/auditbeat-btmp-file-monitoring-glitch-saved-size-or-offset-illogical/332037)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 0\
**Last updated:** [May 1, 2023, 6:47pm UTC](https://discuss.elastic.co/t/auditbeat-btmp-file-monitoring-glitch-saved-size-or-offset-illogical/332037 "2023-05-01T18:47:55Z")

</div>

Hi, I have auditbeat 7.17.8 installed on an RHEL 7 system. RHEL7 rotates out the BTMP file out at the start of every month. So, starting today I am seeing the following message every few seconds in syslog: May 1 12:…

---

## [How to pass in \`current\_unix\_time\` as a value for elasticsearch query?](https://discuss.elastic.co/t/how-to-pass-in-current-unix-time-as-a-value-for-elasticsearch-query/331385)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 5:33pm UTC](https://discuss.elastic.co/t/how-to-pass-in-current-unix-time-as-a-value-for-elasticsearch-query/331385 "2023-05-01T17:33:54Z")

</div>

My ultimate goal is to create a Kibana visualization that shows "How many days have passed since \[today\]". I was told I might be able to create an elasticsearch query that passes in a current\_unix\_time or (new Date()).…

---

## [FileBeat 7.x ARM32 based Image](https://discuss.elastic.co/t/filebeat-7-x-arm32-based-image/331865)

<div class="topic-metadata">

**Author:** [@Kamesh\_Pratapa](https://discuss.elastic.co/u/Kamesh_Pratapa)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 5:31pm UTC](https://discuss.elastic.co/t/filebeat-7-x-arm32-based-image/331865 "2023-05-01T17:31:20Z")

</div>

Hi, I am unable to locate the filebeat and metric beat ARM 32bit architecture based image in the official download location. Can someone help me to point the location ? Regards, Kamesh.

---

## [How can I generate a CEF output](https://discuss.elastic.co/t/how-can-i-generate-a-cef-output/331867)

<div class="topic-metadata">

**Author:** [@CyberGuy](https://discuss.elastic.co/u/CyberGuy)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 4:53pm UTC](https://discuss.elastic.co/t/how-can-i-generate-a-cef-output/331867 "2023-05-01T16:53:42Z")

</div>

I have created a logstash configuration that successfully parses CEF logs and applies certain logic to it. The filter configuration extracts the CEF with a grok filter and then uses the kv plugin to extract the different…

---

## [Reindex corrupted index into a new copy](https://discuss.elastic.co/t/reindex-corrupted-index-into-a-new-copy/330765)

<div class="topic-metadata">

**Author:** [@rivermigue](https://discuss.elastic.co/u/rivermigue)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 4:47pm UTC](https://discuss.elastic.co/t/reindex-corrupted-index-into-a-new-copy/330765 "2023-05-01T16:47:29Z")

</div>

Hello, Is it possible to reindex a corrupted index into a new copy accepting some data loss? I am trying to reindex a corrupted index with the following call: POST \_reindex { "source": { "index": "index001" }, "…

---

## [Elasticsearch binds to all interfaces even with network.host commented out](https://discuss.elastic.co/t/elasticsearch-binds-to-all-interfaces-even-with-network-host-commented-out/331159)

<div class="topic-metadata">

**Author:** [@alexl9](https://discuss.elastic.co/u/alexl9)\
**Replies:** 4\
**Last updated:** [May 1, 2023, 4:32pm UTC](https://discuss.elastic.co/t/elasticsearch-binds-to-all-interfaces-even-with-network-host-commented-out/331159 "2023-05-01T16:32:08Z")

</div>

I installed the latest Elasticsearch but it binds to all interfaces even with network.host commented out, is that expected behavior?

---

## [Logs and no-index fields](https://discuss.elastic.co/t/logs-and-no-index-fields/331009)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 2\
**Last updated:** [May 1, 2023, 4:13pm UTC](https://discuss.elastic.co/t/logs-and-no-index-fields/331009 "2023-05-01T16:13:22Z")

</div>

Has anyone implemented a no-indexing strategy for their logs customers? Meaning, I’d like to allow my customers to insert arbitrary data/structure, but not consume from the finite field count resource, so I want to map …

---

## [Kibana unable to parse syslog logs](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972)

<div class="topic-metadata">

**Author:** [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Replies:** 9\
**Last updated:** [May 1, 2023, 3:52pm UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972 "2023-05-01T15:52:33Z")

</div>

I have a text file which contains data in the below format (syslog). Oct 9 2019 23:39:37 myrtle sshd\[41925\]: pam\_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.49.202.135 user=…

---

## [Moving all shards in an index to the same node](https://discuss.elastic.co/t/moving-all-shards-in-an-index-to-the-same-node/330956)

<div class="topic-metadata">

**Author:** [@andrew3](https://discuss.elastic.co/u/andrew3)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 3:43pm UTC](https://discuss.elastic.co/t/moving-all-shards-in-an-index-to-the-same-node/330956 "2023-05-01T15:43:18Z")

</div>

We want to implement the shrink index API on our cluster. A pre-requisite is that all shards in the to-be-shrunk index must reside on the same node. Currently, this is not the case. What is the simplest way to move all …

---

## [Logstash sometimes parsing sometime not, even though sending the Same message](https://discuss.elastic.co/t/logstash-sometimes-parsing-sometime-not-even-though-sending-the-same-message/331870)

<div class="topic-metadata">

**Author:** [@Prakash111](https://discuss.elastic.co/u/Prakash111)\
**Replies:** 0\
**Last updated:** [May 1, 2023, 12:40pm UTC](https://discuss.elastic.co/t/logstash-sometimes-parsing-sometime-not-even-though-sending-the-same-message/331870 "2023-05-01T12:40:01Z")

</div>

Log message 2023-05-01T05:22:20.154Z \[INFO\] "interSample" {"PID": 1, "Service": "XYZService", "Data": \[\]} some times log stash parsing successfully "\_message\_json\_parsed" some times parse failure "\_grokparsefailure" e…

---

## [How to extract the entire value of a complicated field?](https://discuss.elastic.co/t/how-to-extract-the-entire-value-of-a-complicated-field/330891)

<div class="topic-metadata">

**Author:** [@CyberGuy](https://discuss.elastic.co/u/CyberGuy)\
**Replies:** 6\
**Last updated:** [May 1, 2023, 12:34pm UTC](https://discuss.elastic.co/t/how-to-extract-the-entire-value-of-a-complicated-field/330891 "2023-05-01T12:34:29Z")

</div>

HI guys, I'm trying to create a logstash pipeline that parses incoming CEF logs, apply some logic and then outputs the log in JSON format to the console. Some logs are a bit complicated to parse since the key=value pai…

---

## [Extract all data from a composite aggregation in Power BI/Power Query using after\_key](https://discuss.elastic.co/t/extract-all-data-from-a-composite-aggregation-in-power-bi-power-query-using-after-key/331868)

<div class="topic-metadata">

**Author:** [@Felipe\_Moura\_da\_Silv](https://discuss.elastic.co/u/Felipe_Moura_da_Silv)\
**Replies:** 0\
**Last updated:** [May 1, 2023, 12:34pm UTC](https://discuss.elastic.co/t/extract-all-data-from-a-composite-aggregation-in-power-bi-power-query-using-after-key/331868 "2023-05-01T12:34:00Z")

</div>

Hey guys! I'm having a challenge importing data from an elasticsearch query into Power BI. I'm making the call and the results arrive, but only the limit of 16000 results that the API allows due to performance. I need …

---

## [How to use elastic apm with windows service](https://discuss.elastic.co/t/how-to-use-elastic-apm-with-windows-service/331436)

<div class="topic-metadata">

**Author:** [@Gaurav\_Bissa](https://discuss.elastic.co/u/Gaurav_Bissa)\
**Replies:** 0\
**Last updated:** [May 1, 2023, 2:32am UTC](https://discuss.elastic.co/t/how-to-use-elastic-apm-with-windows-service/331436 "2023-05-01T02:32:24Z")

</div>

I want to implement elastic apm with a windows service which is not hosted on IIS , But I am unable to do so. I can track transactions but not able to implement auto instrumentation Please let me know a solution for th…

---

## [Please tell me about the situation of es hardware resources](https://discuss.elastic.co/t/please-tell-me-about-the-situation-of-es-hardware-resources/330893)

<div class="topic-metadata">

**Author:** [@Astrid\_SRE](https://discuss.elastic.co/u/Astrid_SRE)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 10:18am UTC](https://discuss.elastic.co/t/please-tell-me-about-the-situation-of-es-hardware-resources/330893 "2023-05-01T10:18:13Z")

</div>

hi hello Can you help me analyze it, the current situation of our company is like this 20w logs per second 20T per day What kind of hardware configuration is required What is the configuration of the es cluster, net…

---

## [How to provide own API key in ELK version 8.0.0](https://discuss.elastic.co/t/how-to-provide-own-api-key-in-elk-version-8-0-0/330939)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 6\
**Last updated:** [May 1, 2023, 9:49am UTC](https://discuss.elastic.co/t/how-to-provide-own-api-key-in-elk-version-8-0-0/330939 "2023-05-01T09:49:29Z")

</div>

Hi Team, I want to know how i can provide my own API key in ELK version 8.0.0 I did try - "xpack.security.authc.api\_key.enabled=true" - "xpack.security.authc.api\_key.key=" but no luck getting xpack.security.authc…

---

## [How to migrate data from v5.4 to v8.x.x](https://discuss.elastic.co/t/how-to-migrate-data-from-v5-4-to-v8-x-x/329963)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 8:25am UTC](https://discuss.elastic.co/t/how-to-migrate-data-from-v5-4-to-v8-x-x/329963 "2023-05-01T08:25:25Z")

</div>

Hi ES Community, I have few question, i have to migrate ES v5.4 data into latest ES version(v8.x). What would be correct step for this kind data migration? Should i use elasticdump tool to migrate data from old cluster…

---

## [Filebeat kubernetes unable to format json logs into fields](https://discuss.elastic.co/t/filebeat-kubernetes-unable-to-format-json-logs-into-fields/330795)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 2\
**Last updated:** [May 1, 2023, 5:48am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-unable-to-format-json-logs-into-fields/330795 "2023-05-01T05:48:55Z")

</div>

Hello, i want to ingested containers json log data using filebeat deployed on kubernetes, i am able to ingest the logs to but i am unable to format the json logs in to fields following is the logs visible in kibana …

---

## [How to setup username and password in EFK in helm charts](https://discuss.elastic.co/t/how-to-setup-username-and-password-in-efk-in-helm-charts/331038)

<div class="topic-metadata">

**Author:** [@root\_linux](https://discuss.elastic.co/u/root_linux)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 4:18am UTC](https://discuss.elastic.co/t/how-to-setup-username-and-password-in-efk-in-helm-charts/331038 "2023-05-01T04:18:30Z")

</div>

Hi, I have configured EFK using helm charts. But it is not asking for username and password. Could anyone help me how can I configure username and password in EFK using helm charts?

---

## [After upgrading from 7.1 to 8.7, I lost my data](https://discuss.elastic.co/t/after-upgrading-from-7-1-to-8-7-i-lost-my-data/331126)

<div class="topic-metadata">

**Author:** [@toshihisa-nakamura](https://discuss.elastic.co/u/toshihisa-nakamura)\
**Replies:** 2\
**Last updated:** [May 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/after-upgrading-from-7-1-to-8-7-i-lost-my-data/331126 "2023-05-01T04:05:29Z")

</div>

After upgrading from 7.1 to 8.7, I lost my data. With Version 8.7, I want to be able to enter data into Elasticsearch and display graphs in Kibana as before. I've been using it for several years just to send weather da…

---

## [Failed to Parse date](https://discuss.elastic.co/t/failed-to-parse-date/331445)

<div class="topic-metadata">

**Author:** [@valleram](https://discuss.elastic.co/u/valleram)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 2:58am UTC](https://discuss.elastic.co/t/failed-to-parse-date/331445 "2023-05-01T02:58:25Z")

</div>

Hi All, I'm trying to parse dates with format 1/3/2022. I've tried to parse it using following mapping M/d/YYYY but Kibana is showing a completely different result. See example below. Ingested date: Date showed in …

---

## [Remote clusters for basic/platinum , onprem/cloud license](https://discuss.elastic.co/t/remote-clusters-for-basic-platinum-onprem-cloud-license/330668)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 10\
**Last updated:** [May 1, 2023, 12:43am UTC](https://discuss.elastic.co/t/remote-clusters-for-basic-platinum-onprem-cloud-license/330668 "2023-05-01T00:43:55Z")

</div>

Hi, We have several Elastic clusters on-premises and we plan to create a few new ones on Azure cloud. All of them are self-managed version 8.6. The purpose of all Elasticsearch clusters is data analysis in Kibana, so I…

---

## [Elasticsearch G1GC over CMS in resolving the GC overhead](https://discuss.elastic.co/t/elasticsearch-g1gc-over-cms-in-resolving-the-gc-overhead/330744)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 3\
**Last updated:** [April 30, 2023, 11:21pm UTC](https://discuss.elastic.co/t/elasticsearch-g1gc-over-cms-in-resolving-the-gc-overhead/330744 "2023-04-30T23:21:48Z")

</div>

We are using the ES 7.3 with CMS GC and we are preparing for the rolling upgrade to 7.17 which supports G1GC only We are getting the GC overhead curently, \[2023-04-25T02:00:41,085\]\[WARN \]\[o.e.m.j.JvmGcMonitorService\] \[…

---

## [Move ilm based indices to new ILM policy](https://discuss.elastic.co/t/move-ilm-based-indices-to-new-ilm-policy/330793)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:18pm UTC](https://discuss.elastic.co/t/move-ilm-based-indices-to-new-ilm-policy/330793 "2023-04-30T23:18:07Z")

</div>

Hi Team, Few months back we have created one ILM policy for all indices. It was working fine then now our business need to is to create different policy for different indices the idea is to rollover some indices in 3 da…

---

## [Mappings Issue](https://discuss.elastic.co/t/mappings-issue/330797)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:17pm UTC](https://discuss.elastic.co/t/mappings-issue/330797 "2023-04-30T23:17:15Z")

</div>

Hi, I have a field in my index with the mapping and custom analyzer has followed: Mapping: "BookingNo" : { "type" : "text", "fields" : { "lowercase\_keyword" : { "type" : "text", "analyzer" : "lowercase\_keyword\_an…

---

## [How to index audio/video files to kibana](https://discuss.elastic.co/t/how-to-index-audio-video-files-to-kibana/330834)

<div class="topic-metadata">

**Author:** [@AdityaKhajuria](https://discuss.elastic.co/u/AdityaKhajuria)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:15pm UTC](https://discuss.elastic.co/t/how-to-index-audio-video-files-to-kibana/330834 "2023-04-30T23:15:08Z")

</div>

Hi, Im trying to index audio/video files to kibana. I am able to get audio in a field by setting Format-URL and type-Audio in index pattern. But i want my logstash to index my audio/video files to kibana.

---

## [Search template Kibana](https://discuss.elastic.co/t/search-template-kibana/331053)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:02pm UTC](https://discuss.elastic.co/t/search-template-kibana/331053 "2023-04-30T23:02:07Z")

</div>

Is there a way to use search template within kibana page like in discover ? I know we can use elasticsearch search template in devTools , but the output of the result is in json which not very visual I want to display…

---

## [Elasticsearch 8.7.0 Installation issue: elasticsearch.bat cmd automatic closes without installation](https://discuss.elastic.co/t/elasticsearch-8-7-0-installation-issue-elasticsearch-bat-cmd-automatic-closes-without-installation/331156)

<div class="topic-metadata">

**Author:** [@M4MURARI](https://discuss.elastic.co/u/M4MURARI)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 10:58pm UTC](https://discuss.elastic.co/t/elasticsearch-8-7-0-installation-issue-elasticsearch-bat-cmd-automatic-closes-without-installation/331156 "2023-04-30T22:58:55Z")

</div>

After unzipping the elasticsearch-8.7.0-windows-x86\_64.zip when I click on elasticsearch.bat of bin folder, It automatically closes without full installation. One solution I tried was xpack.security.transport.ssl.enable…

---

## [Issue with Elasticsearch indexes](https://discuss.elastic.co/t/issue-with-elasticsearch-indexes/331064)

<div class="topic-metadata">

**Author:** [@milank2](https://discuss.elastic.co/u/milank2)\
**Replies:** 9\
**Last updated:** [April 30, 2023, 10:56pm UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-indexes/331064 "2023-04-30T22:56:38Z")

</div>

Hello everyone, I am new to ELK and the issue I am experiencing is that indexes are after 3 days reduces to 25x bytes and 0 documents. We are viewing index patterns in Kibana but it will display the 3 days only. Nothing…

---

## [No incoming data to Logstash Output from Elastic Agents - Only Elasticsearch ouptut works](https://discuss.elastic.co/t/no-incoming-data-to-logstash-output-from-elastic-agents-only-elasticsearch-ouptut-works/331350)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 5\
**Last updated:** [April 30, 2023, 9:36pm UTC](https://discuss.elastic.co/t/no-incoming-data-to-logstash-output-from-elastic-agents-only-elasticsearch-ouptut-works/331350 "2023-04-30T21:36:01Z")

</div>

8.7 stack here After I setup a logstash output in Fleet, and set a policy to use that logstash ouptut for integrations, no data comes to it basically. When I switch the output for integrations to Elasticsearch instead …

---

## [Log stash behavior when output plug-in not reachable](https://discuss.elastic.co/t/log-stash-behavior-when-output-plug-in-not-reachable/331376)

<div class="topic-metadata">

**Author:** [@eth](https://discuss.elastic.co/u/eth)\
**Replies:** 0\
**Last updated:** [April 30, 2023, 6:14pm UTC](https://discuss.elastic.co/t/log-stash-behavior-when-output-plug-in-not-reachable/331376 "2023-04-30T18:14:03Z")

</div>

I am using logstash 7 with syslog as output plugin. The syslog server is not reachable for a quite a long time and persistent queue is growing as expected to the limit. But the persistent queue data size is growing bey…

[Previous page](https://discuss.elastic.co/latest.md?page=692)

[Next page](https://discuss.elastic.co/latest.md?page=694)
